LIVE · cybersecurity feed
Live wire
ai

PCI SSC calls for human approval of AI agent actions involving cardholder data

The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of…

ZeroDay News ·

Source: Help Net Security

The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of existing PCI standards, which take precedence over the new recommendations.

A core recommendation emphasizes a "least agency" approach, limiting AI systems to only the access and capabilities necessary for their assigned tasks. Organizations are advised to define an AI system's purpose, permissions, and data access before deployment. A designated human individual should formally accept responsibility for AI output, and specific actions requiring human approval must be clearly defined. For AI agents with access to cleartext cardholder data, explicit human approval is recommended for any actions involving that data.

The guidance also addresses the management of sensitive data and credentials. AI systems should not handle, generate, or manage unprotected high-impact secrets such as passwords or cryptographic keys. Instead, credentials should be managed via secrets-management tools and kept out of source code, prompts, AI context, outputs, and logs. When random values are needed, a trusted random-number generator should be used, with values for passwords or cryptographic keys potentially needing to remain entirely outside the AI system. The PCI SSC recommends using encrypted or tokenized payment data whenever possible, with independent data-loss prevention controls. Logs should support investigations without retaining sensitive payment information.

Organizations are urged to maintain an AI inventory and bill of materials, detailing models, versions, hosting, integrations, data-use and retention policies, and intended users. An acceptable-use policy and technical controls are also recommended to identify and restrict "shadow AI"—unapproved tools used by employees. Access restrictions should be enforced through independent controls like identity-management policies and network isolation. The guidance advises against combining sensitive data access, external communications, and unrestricted input from untrusted sources within a single AI system. If a workflow requires all three, responsibilities should be separated among agents with different permissions.

Testing safeguards before extensive functional or user-acceptance testing is crucial, including adversarial testing to check for bypasses. Continuous monitoring and revalidation throughout deployment are necessary to detect behavioral changes. Review processes should also account for potential "excessive trust" in AI output, which could lead reviewers to overlook mistakes. For monitored autonomous AI, organizations should define permitted actions, approval requirements, shutdown triggers, and procedures for reversing changes, with a human remaining ultimately responsible.

The PCI SSC warns that AI can accelerate vulnerability discovery, exploit development, and social engineering. Recommended defenses include ongoing vulnerability monitoring, prioritizing findings and patches, limiting services and permissions, isolating legacy systems, using phishing-resistant authentication, encrypting sensitive data, and containing breach impacts. AI-generated code and patches should undergo security and functional testing, with reviews checking for embedded credentials, unsuitable dependencies, newly introduced weaknesses, and whether fixes address the underlying problem.

When engaging external AI providers with access to sensitive data, organizations should assess them under applicable third-party service provider requirements. Agreements should clarify responsibility for sensitive information, explicitly prohibit using the organization's data for AI training, provide visibility into subcontractors, and set breach notification terms. Incident response plans and periodic testing should cover prompt injection, model poisoning, actions outside approved scope, and unauthorized AI tools accessing sensitive data.

PCI DSS scoping for AI systems should consider deployment, isolation, access to account data (including data used for training), and the system's ability to affect the security of cardholder-data systems. Access to encrypted or tokenized data, combined with tools that can decrypt or detokenize it, should be treated as access to readable data.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Companies want autonomous IT operations but hesitate to let AI act alone

Ninety percent of companies anticipate a shift toward autonomous IT operations within the next two years, envisioning agentic AI systems that independently plan and execute multi-step tasks. However, a significant majority, 77 percent, express hesitation in allowing AI to make operational decisions without human approval. This suggests that most organizations currently aim for a model where a…

vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

security

Co-creator of Empire Market dark web marketplace given 40-year sentence

Raheim Hamilton, a co-creator of the dark web marketplace Empire Market, has been sentenced to 40 years in federal prison for his role in operating the platform. The 30-year-old Virginia native pleaded guilty earlier this year to a drug conspiracy charge and was ordered by U.S. District Judge Steven Seeger to forfeit over $100 million in Bitcoin and several properties in Virginia, in addition…

vulnerability

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

breach

Thousands of wind and solar park systems sit exposed on the internet across Europe

A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces…